Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05030
HistoryDec 19, 2021 - 12:00 a.m.

Quality Open Software logback remote code execution vulnerability

2021-12-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
20

0.016 Low

EPSS

Percentile

87.3%

Quality Open Software logback is a logging framework for Java applications from Quality Open Software of Switzerland. quality Open Software logback in versions 1.2.7 and earlier is vulnerable to remote code execution, which stems from a failure to effectively filter user input. The vulnerability stems from a failure to effectively filter user input, which can be exploited to craft malicious configurations that allow the execution of arbitrary code loaded from an LDAP server.

CPENameOperatorVersion
quality open software logbackle1.2.7